Ransomware payments cratered in 2025, but attacks surged to record highs

2026-03-04T22:49:49Z5a3cadd5fa5a66558121541f0c5f62fb5933e494defe0bad852c2f13e6a7db40
AI-augmented attacksAnthropic ClaudeCISACisco SD-WANFive EyesFortiGateLazarus GroupMedusa ransomwareShinyHuntersSolarWinds Serv-UUNC2814data-breachextortionpatchingransomwareremote-code-executionsupply-chainvulnerabilities

What happened

A run of high-impact security stories: ransomware payments plunged in 2025 even as attack volume hit record highs, with new and rebranded gangs proliferating. Multiple large data breaches and extortion campaigns were reported (ManoMano subcontractor exfiltration allegedly ~37M accounts; ShinyHunters leaks including Odido and Wynn Resorts; French bank-account database theft). Nation-state and criminal activity continues (UNC2814 spreadsheet-based espionage; North Korea’s Lazarus using Medusa ransomware). Urgent vulnerability advisories and active exploitation featured prominently — Five Eyes on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
5a3cadd5fa5a66558121541f0c5f62fb5933e494defe0bad852c2f13e6a7db40
Enrichment time
2026-03-04T22:49:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.